PatchSiren

BlackBerry CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM BlackBerry CVE published 2026-08-11

CVE-2026-18247

A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session. This vulnerability is particularly concerning for administrators and users of AtHoc IWS, as it could lead to unauthorized actions within the victim's session. The vulnerability has a CVSS score of 5.3, [truncated]

MEDIUM BlackBerry CVE published 2026-07-28

CVE-2026-18085

CVE-2026-18085 is an Improper Input Validation vulnerability in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier. This vulnerability allows for Arbitrary File Download and Potential Denial of Service. Organizations should review the official CVE record and NVD entry for details. The CVE record was published on 2026-07-28T17:16:38.150Z and has not been modified since then. Th [truncated]

HIGH BlackBerry CVE published 2026-07-28

CVE-2026-18084

The CVE record describes an Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console, which allows Cross-Site Scripting (XSS). The vulnerability affects UEM 12.23.0 QF8 or earlier. The CVSS score is 8.6 with a High severity. Organizations should be aware of this vulnerability and take necessary actions to mitigate the risk of Cross-Site Scripting (XSS) [truncated]

HIGH Blackberry CVE published 2017-03-03

CVE-2016-3127

CVE-2016-3127 is a high-severity information disclosure issue in BlackBerry Good Control Server's logging implementation. The supplied CVE description says that versions earlier than 2.3.53.62 can allow remote attackers to gain and use encryption keys that were written to diagnostic logs, which may then be used to access certain resources in a customer's Good deployment. The risk is centered on exposure o [truncated]

MEDIUM Blackberry CVE published 2017-01-13

CVE-2017-3890

CVE-2017-3890 is a reflected cross-site scripting (XSS) vulnerability in BlackBerry WatchDox Server components. According to the NVD record, it affects Appliance-X version 1.8.1 and earlier, and vAPP versions 4.6.0 through 5.4.1. A remote attacker can induce a user to click a malicious link, causing script to run in the context of the affected browser.

HIGH Blackberry CVE published 2017-01-13

CVE-2016-3130

CVE-2016-3130 is a high-severity information disclosure issue affecting BlackBerry Enterprise Server (BES) 12 through 12.5.2. According to the CVE record, an attacker able to sniff traffic between the Core and Management Console during a login attempt could obtain local or domain credentials for an administrator or user account. Because the issue involves credential exposure, affected organizations should [truncated]

HIGH Blackberry CVE published 2017-01-13

CVE-2016-3128

CVE-2016-3128 is a spoofing vulnerability in the core of BlackBerry Enterprise Server (BES) 12 through 12.5.2. According to the CVE record, a remote attacker could use information tied to a legitimately enrolled device to enroll an illegitimate device, access device parameters for the BES, or send false information to the BES. NVD lists the issue as CVSS 3.0 8.2 (HIGH) with network attack vector, no privi [truncated]